{
 "id": "WPSEC-2026-0634",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0634/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0634/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0634/index.md",
 "title": "Product Feed Manager for WooCommerce <= 8.0.31 - Unauthenticated Sensitive Information Exposure of SFTP Password via Log Files",
 "description": "The Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 8.0.0 up to, and including, 8.0.31. When an SFTP login failed during a feed upload, the plaintext SFTP password was included in the error message, which was written together with the SFTP host and username to a predictably named feed log file in the uploads directory that was protected only by an Apache .htaccess rule. This makes it possible for unauthenticated attackers to read stored SFTP credentials from the log file on servers that do not apply that rule, such as Nginx, after an SFTP login for a feed upload has failed.",
 "plugin": {
  "slug": "webappick-product-feed-for-woocommerce",
  "name": "Product Feed Manager for WooCommerce",
  "full_name": "Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels",
  "wordpress_org": "https://wordpress.org/plugins/webappick-product-feed-for-woocommerce/",
  "advisories_url": "https://wpsec.com/vuln/plugin/webappick-product-feed-for-woocommerce/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/webappick-product-feed-for-woocommerce"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-532"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.9,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "8.0.0",
    "from_inclusive": true,
    "to": "8.0.32",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 8.0.0 before 8.0.32"
  ]
 },
 "introduced_in": "8.0.0",
 "fixed_in": "8.0.32",
 "remediation": "Update to 8.0.32 or later.",
 "fix_released": "2026-10-07T09:41:10+00:00",
 "published": "2026-10-08T09:45:16+00:00",
 "updated": "2026-10-07T12:20:06.261851+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0634/",
  "https://plugins.svn.wordpress.org/webappick-product-feed-for-woocommerce/tags/8.0.32/",
  "https://wordpress.org/plugins/webappick-product-feed-for-woocommerce/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/webappick-product-feed-for-woocommerce",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}